This video will show the process of creating a Query-based rule in Elastic SIEM, which searches the defined indices and creates an alert when a document matches the rule’s query.
Link to the example rule created in the video https://gist.github.com/austinsonger/...
If you have any additional questions on the video you can join my slack group for this channel.
http://bit.ly/Songertech-Slack